Disclosures
Findings from the group that reached a CVE and a vendor fix. Scattered through prose they read as parentheses; collected, they are the clearest single statement of what the research actually changed.
| Identifier | Product or protocol | Finding | Source |
|---|---|---|---|
| CVE-2026-23670 | Microsoft Windows: Virtualisation-Based Security, HVCI and the secure kernel | Software-only memory aliasing gives arbitrary read/write and breaks every guarantee built on VBS | Download More RAM, USENIX Security 2026 |
| CVE-2021-44718 | wolfSSL 5.0.0 and earlier: TLS client | Client accepts server-only TLS messages, so a machine-in-the-middle can force an infinite loop | Grey-box state machine learning, CCS 2022 |
| CVE-2020-24686 | ABB AC500 V2 PLC: web visualisation | Uncontrolled resource consumption stops operators monitoring PLC state remotely | Learning From Vulnerabilities, CyberICPS 2020 |
| CVE-2020-17497 | iNet Wireless Daemon (IWD) 1.8 and earlier: 802.11 4-way handshake | Retransmitting EAPOL message 4/4 triggers a PTK reinstallation, allowing replay and decryption | Grey-box state machine learning, CCS 2022 |
| CVE-2020-15677 | Mozilla Firefox < 81, Firefox ESR and Thunderbird < 78.3 | Open redirect lets a download dialog name the legitimate site rather than where the file really came from | Reported to Mozilla, MFSA2020-42 |
| CVE-2020-12524 | Phoenix Contact BTP 2043W / 2070W / 2102W touch panels | Uncontrolled resource consumption leaves the HMI unresponsive and its display stale | Learning From Vulnerabilities, CyberICPS 2020 |
| CVE-2020-7592 | Siemens KTP700 HMI | Configuration sent in the clear, leaking the content due to be shown on the panel | Learning From Vulnerabilities, CyberICPS 2020 |
| CVE-2019-6540 | Medtronic Conexus telemetry: implantable defibrillators, CareLink monitors and programmer | Telemetry is unencrypted, so short-range radio access exposes patient and device data | Marin et al., ACSAC 2016 |
| CVE-2019-6538 | Medtronic Conexus telemetry: implantable defibrillators, CareLink monitors and programmer | No authentication, so an attacker in radio range can inject, replay and modify traffic, and read and write device memory | Marin et al., ACSAC 2016 |
| CVE-2018-0412 | Cisco Small Business 100 and 300 series wireless access points, EAPOL | Manipulated EAPOL messages downgrade the cipher from AES-CCMP to the weaker WPA-TKIP | WPA 4-way handshake state learning, ESORICS 2018 |
We follow coordinated disclosure: vendors get a fixed window to ship a fix before anything is published, and we work with national CERTs where the affected estate is large.
If you want to discuss a finding in something we have worked on, email T.Chothia@bham.ac.uk.